Skip to content

fix: patch vulnerabilities and bump outdated dependencies - #7593

Closed
waldekmastykarz wants to merge 2 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-dependency-security-updates
Closed

waldekmastykarz wants to merge 2 commits into
pnp:mainfrom
waldekmastykarz:waldekmastykarz-dependency-security-updates

Conversation

@waldekmastykarz

Copy link
Copy Markdown
Member

Summary

  • carries forward every change from fix: patch vulnerabilities and bump outdated dependencies #7587
  • updates cooldown-eligible direct dependencies and security overrides
  • applies compatible transitive fixes for @humanfs/node, @xmldom/xmldom, brace-expansion, js-yaml, and undici
  • retains Zod 4.5.4 because 4.6.5 breaks the required 100% coverage instrumentation
  • leaves major-version upgrades for separate compatibility work

Security status

npm audit reports 0 vulnerabilities.

Not auto-applied

Major updates remain for @azure/msal-node, @types/node, eslint-plugin-mocha, mocha, typescript, and several overrides. Pre-release-only updates for @typescript-eslint were also skipped.

Validation

  • npm run build
  • npm test
  • 16,163 tests passing
  • 100% statement, branch, function, and line coverage

Supersedes #7587.

waldekmastykarz and others added 2 commits September 28, 2026 09:06
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
Co-authored-by: Copilot App <223556219+Copilot@users.noreply.github.com>
@waldekmastykarz

Copy link
Copy Markdown
Member Author

Superseded by #7620, which includes all changes from this PR plus the latest cooldown-eligible dependency and vulnerability fixes.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant